Hi,
I also have the same question.
If anyone can answer this, we would greatly appreciate it.
Thanks.
Thanks a lot syed_rizvi...
Your Welcome. Here are some good examples of creating dynamic watchlists.
McAfee KnowledgeBase - How to filter the SIEM for users ending in a dollar ($) sign
As mentioned by syed_rizvi, they are case Sensitive.
For Displays, Reports, and ELM Searches there are options for Case Insensitive Searches.
However for Correlation Rules and Field Match Alarm logic, there is not an option for Case Insensitive.
I submitted a new "Idea" (PER) on the new Ideas Forum for this, the more people that Vote on it, the higher priority it might receive when being reviewed and presented to Development.
To sign up for the new Ideas forum and begin submitting your Ideas, go to:
https://www51.v1ideas.com/IntelIdeas/ISecGForum
For more information, see KB60021 ( https://kc.mcafee.com/corporate/index?page=content&id=KB60021).
rth67 wrote:
However for Correlation Rules and Field Match Alarm logic, there is not an option for Case Insensitive.
I submitted a new "Idea" (PER) on the new Ideas Forum for this, the more people that Vote on it, the higher priority it might receive when being reviewed and presented to Development.
To sign up for the new Ideas forum and begin submitting your Ideas, go to:
https://www51.v1ideas.com/IntelIdeas/ISecGForum
For more information, see KB60021 ( https://kc.mcafee.com/corporate/index?page=content&id=KB60021).
Great PER idea
The data type may influence the outcome here.
In the Filters panel you will see the option case insensitive option - Aa - for some, but not all, fields. If that option is present then case sensitivity will be in play, if it is not present, for example on a alphanumeric MAC address or Protocol field, you may have to experiment to be sure.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA